Security Center
安全情报屋
报告类型 当前榜单
情报总数 94 条
板块条数 94 条
生成时间 08-29 00:00
📚 安全情报馆 · 2026-08-29
4 块

🛡️ 每日安全情报

🛡️ AI 安全情报日报 · 2026-08-29

_2026-08-29 · 共筛出 139 条 ≥4★_

1. 2022_PoC-MSDT-Follina-CVE-2022-30190 exploit 🔓 ★★★★★

📋 Exploit for CVE-2022-30190. CVSS 9.3.

2. 4B5F5F4Bp exploit 🔓 ★★★★★

📋 Exploit for CVE-2017-0075. CVSS 7.6.

3. AI与云安全事件案例分析周报|2026.08.24 - 2026.08.28 🔓 ⚔️ 📄 ★★★★★

📋 原创 星云实验室 2026-08-28 18:14 北京 本周风险集中在高能力智能体失控后的横向协作、AI 基础设施被现实攻击流量穿透,以及本地模型与共享 GPU 的隔离边界失守。 事件一 OpenAI 针对 Hugging Face 事件

4. AI安全专题周报(20260828) 🔓 📄 ★★★★★

📋 报告编号: TIC-202608-AI03 报告周期: 2026年8月22日—8月28日 一、报告概述 基于360威胁情报中心对本期公开网络安全素材的整理与分析,本周AI安全风险主要集中在AI应用与Agent运行环境漏洞、提示注入和模型配置

5. AnySniff exploit 🔓 ★★★★★

📋 Exploit for CVE-2024-52940. CVSS 7.5.

6. BlackSnufkin exploit 🔓 ★★★★★

📋 Exploit for CVE-2025-52915 and CVE-2026-3609. CVSS 7.8.

7. COM-Code-Helper exploit 🔓 ★★★★★

📋 Exploit.

8. CVE-2014-8609-POC exploit 🔓 ★★★★★

📋 Exploit for CVE-2014-8609. CVSS 7.2.

9. CVE-2017-12636 exploit 🔓 ★★★★★

📋 Exploit for CVE-2017-12636. CVSS 9.

10. CVE-2018-17254 exploit 🔓 ★★★★★

📋 Exploit for CVE-2018-17254. CVSS 9.8.

11. CVE-2019-1006 exploit 🔓 ★★★★★

📋 Exploit for CVE-2019-1006. CVSS 7.5.

12. CVE-2019-14319 exploit 🔓 ★★★★★

📋 Exploit for CVE-2019-14319. CVSS 6.5.

13. CVE-2019-16278-Nostromo_1.9.6-RCE exploit 🔓 ★★★★★

📋 Exploit for CVE-2019-16278. CVSS 9.8.

14. CVE-2019-2107 exploit 🔓 ★★★★★

📋 Exploit for CVE-2019-2107. CVSS 9.3.

15. CVE-2019-9465 exploit 🔓 ★★★★★

📋 Exploit for CVE-2019-9465. CVSS 5.5.

---

其他 124 条

🚨 漏洞预警

🔴 CRITICAL · 58 条

1. CVE-2026-9198 🔥 ⚡近期活跃 `CVSS 9.8`

🎯 受影响:IBM Langflow OSS 1.0.0 through 1.10.0

📋 简介:IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments

🔗 参考:

2. CVE-2017-17485 🔥 ⚡近期活跃 `CVSS 9.8`

🎯 受影响:FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3

📋 简介:FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw.

🔗 参考:

3. CVE-2025-24813 🔥 ⚡近期活跃 `CVSS 10.0`

🎯 受影响:Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information dis

📋 简介:Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Default Servlet in Apache Tomcat.

🔗 参考:

4. CVE-2022-42889 🔥 ⚡近期活跃 `CVSS 9.8`

🎯 受影响:Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated

📋 简介:Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded.

🔗 参考:

5. CVE-2026-73125 `CVSS 9.8`

🎯 受影响:Ebyte device web management interface does not consistently enforce

📋 简介:Ebyte device web management interface does not consistently enforce

authentication before granting access to administrative functionality.

🔗 参考:

6. CVE-2026-82266 `CVSS 9.8`

🎯 受影响:Redpanda through 26.2.2 binds the Admin API to 0.0.0.0:9644 with admin_api_require_auth defaulting t

📋 简介:Redpanda through 26.2.2 binds the Admin API to 0.0.0.0:9644 with admin_api_require_auth defaulting to false, treating unauthenticated requests as superusers.

🔗 参考:

7. CVE-2026-33017 🔥 ⚡近期活跃 `CVSS 9.8`

🎯 受影响:Langflow

📋 简介:Langflow is a tool for building and deploying AI-powered agents and workflows.

🔗 参考:

8. CVE-2026-68929 `CVSS 9.3`

🎯 受影响:FastGPT

📋 简介:FastGPT is an open-source LLM platform for building AI applications on a knowledge base.

🔗 参考:

9. CVE-2026-81578 `CVSS 8.8`

🎯 受影响:An improper access control vulnerability exists in the web management interface of PaperCut MF and P

📋 简介:An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG.

🔗 参考:

10. CVE-2026-61800 `CVSS 9.1`

🎯 受影响:Wazuh

📋 简介:Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads.

🔗 参考:

11. CVE-2026-10036 🔥 `CVSS 8.8`

🎯 受影响:SpeechBrain

📋 简介:SpeechBrain before 1.1.1 contains an arbitrary code execution vulnerability that allows attackers to execute arbitrary code by supplying a crafted CKPT.yaml checkpoint metadata file parsed with PyYAML's unsafe loader during candidate enumeration in Checkpointer.recover_if_poss...

🔗 参考:

12. CVE-2022-30190 🔥 ⚡近期活跃 `CVSS 9.3`

🎯 受影响:A remote code execution vulnerability exists when MSDT

📋 简介:A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word.

🔗 参考:

13. CVE-2026-18717 `CVSS 9.1`

🎯 受影响:ASE2000 2.35 through 2.37

📋 简介:ASE2000 2.35 through 2.37 is vulnerable to an improper certificate validation vulnerability, which may allow an attacker to impersonate the trusted peer, complete the TLS handshake, and read or modify protected communications.

🔗 参考:

14. CVE-2026-3627 `CVSS 9.1`

🎯 受影响:IBM Concert 1.0.0 through 2.3.1

📋 简介:IBM Concert 1.0.0 through 2.3.1 is vulnerable to SQL injection.

🔗 参考:

15. CVE-2026-75813 `CVSS 8.7`

🎯 受影响:Certain configuration endpoints may lack proper server-side

📋 简介:Certain configuration endpoints may lack proper server-side

authorization checks, allowing unauthorized users to access or modify

sensitive device settings.

🔗 参考:

16. CVE-2026-82017 `CVSS 8.6`

🎯 受影响:IGEL OS 12

📋 简介:IGEL OS 12 before 12.7.6 and IGEL OS 11 before 11.11.150 contain a boot registry parameter injection vulnerability that allows attackers with physical access to execute arbitrary Linux loader parameters by writing to an unencrypted and unsigned configuration area read by the s...

🔗 参考:

17. CVE-2026-82283 `CVSS 8.6`

🎯 受影响:VoltAgent through 2.1.20 fails to validate conversation ownership in memory API handlers, allowing a

📋 简介:VoltAgent through 2.1.20 fails to validate conversation ownership in memory API handlers, allowing authenticated users to access other users' conversations.

🔗 参考:

18. CVE-2026-54745 `CVSS 10`

🎯 受影响:Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows.

📋 简介:Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows.

🔗 参考:

19. CVE-2014-0160 🔥 ⚡近期活跃 `CVSS 7.5`

🎯 受影响:The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heart

📋 简介:The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by...

🔗 参考:

20. CVE-2026-18527 `CVSS 9.9`

🎯 受影响:IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow

📋 简介:IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow a remote attacker to gain elevated privileges, caused by ARE GUI component processing.

🔗 参考:

21. CVE-2026-54083 `CVSS 8.1`

🎯 受影响:Wazuh

📋 简介:Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads.

🔗 参考:

22. CVE-2026-82291 `CVSS 8.1`

🎯 受影响:HeyForm

📋 简介:HeyForm before 3.0.0-rc.8 reflects the request Origin header in CORS responses while allowing credentials, enabling cross-origin requests with authentication.

🔗 参考:

23. CVE-2026-19295 `CVSS 9.9`

🎯 受影响:IBM Langflow OSS 1.0.0 through 1.11.1

📋 简介:IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system commands in the server process by saving a flow with a crafted type field value and triggering a build of a wrapper flow that references it.

🔗 参考:

24. CVE-2026-19286 `CVSS 9.8`

🎯 受影响:IBM Langflow OSS 1.0.0 through 1.11.1 could

📋 简介:IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary code due to improper enforcement of security restrictions on the A2A public endpoint.

🔗 参考:

25. CVE-2026-82277 `CVSS 9.8`

🎯 受影响:Argo Rollouts dashboard through 1.10.0 binds to all interfaces and exposes mutating Rollout operatio

📋 简介:Argo Rollouts dashboard through 1.10.0 binds to all interfaces and exposes mutating Rollout operations without authentication, authorization, or CSRF protection.

🔗 参考:

26. CVE-2026-55068 `CVSS 9.3`

🎯 受影响:free5GC

📋 简介:free5GC is an open-source implementation of the 5G core network.

🔗 参考:

27. CVE-2026-55378 `CVSS 9.3`

🎯 受影响:JS Recon

📋 简介:JS Recon is a JavaScript enumeration and SAST tool.

🔗 参考:

28. CVE-2026-71187 `CVSS 9.8`

🎯 受影响:The Ebyte device relies on client side authentication logic that can be

📋 简介:The Ebyte device relies on client side authentication logic that can be

reproduced by unauthenticated users.

🔗 参考:

29. CVE-2026-82082 `CVSS 9.8`

🎯 受影响:NUMail developed by Green-Computing has an OS Command Injection vulnerability. Unauthenticated remot

📋 简介:NUMail developed by Green-Computing has an OS Command Injection vulnerability.

🔗 参考:

30. CVE-2026-82329 `CVSS 9.8`

🎯 受影响:JFrog Artifactory

📋 简介:JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.

🔗 参考:

31. CVE-2026-13086 `CVSS 9.3`

🎯 受影响:A stack-based buffer overflow in the epm (Endpoint Protection Manager) service used by the deprecate

📋 简介:A stack-based buffer overflow in the epm (Endpoint Protection Manager) service used by the deprecated Mobile Security feature in WatchGuard Fireware OS allows an unauthenticated remote attacker to execute arbitrary code.

🔗 参考:

32. CVE-2026-19313 `CVSS 9.3`

🎯 受影响:An heap overflow vulnerability in the WatchGuard Fireware OS iked process

📋 简介:An heap overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.

🔗 参考:

33. CVE-2026-19315 `CVSS 9.3`

🎯 受影响:A type confusion vulnerability in the iked process of WatchGuard Fireware OS

📋 简介:A type confusion vulnerability in the iked process of WatchGuard Fireware OS allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.

🔗 参考:

34. CVE-2026-19318 `CVSS 9.3`

🎯 受影响:A stack-based buffer overflow vulnerability in the WatchGuard Fireware OS iked process

📋 简介:A stack-based buffer overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.

🔗 参考:

35. CVE-2026-82244 `CVSS 9.4`

🎯 受影响:Budibase

📋 简介:Budibase versions before 3.41.3 contain a remote code execution vulnerability in plugin handling that allows authenticated admin users to execute arbitrary code by uploading a malicious plugin tarball.

🔗 参考:

36. CVE-2026-55565 `CVSS 9.9`

🎯 受影响:Yamcs

📋 简介:Yamcs is a mission control framework.

🔗 参考:

37. CVE-2026-55634 `CVSS 9.9`

🎯 受影响:Pimcore

📋 简介:Pimcore is an Open Source Data & Experience Management Platform.

🔗 参考:

38. CVE-2026-55559 `CVSS 9.8`

🎯 受影响:Yamcs

📋 简介:Yamcs is a mission control framework.

🔗 参考:

39. CVE-2026-69658 `CVSS 9.8`

🎯 受影响:MQTT credentials and control traffic are transmitted in cleartext,

📋 简介:MQTT credentials and control traffic are transmitted in cleartext,

exposing sensitive information to network-level attackers.

🔗 参考:

40. CVE-2026-76179 `CVSS 9.8`

🎯 受影响:An improper protection of authentication tokens vulnerability exists in

📋 简介:An improper protection of authentication tokens vulnerability exists in

certain Ebyte gateway products.

🔗 参考:

41. CVE-2026-76943 `CVSS 9.8`

🎯 受影响:Xiiaozet LK100Wt

📋 简介:Xiiaozet LK100Wt contains an authentication weakness within an

administrative service that may allow an attacker to bypass intended

access controls and obtain command execution capabilities.

🔗 参考:

42. CVE-2026-78032 `CVSS 9.8`

🎯 受影响:SOY CMS

📋 简介:SOY CMS contains an issue with deserialization of untrusted data.

🔗 参考:

43. CVE-2026-78239 `CVSS 9.8`

🎯 受影响:Xiiaozet LK100W exposes a critical management function that can be

📋 简介:Xiiaozet LK100W exposes a critical management function that can be

invoked without authentication, allowing a remote attacker to enable

administrative services that should be restricted.

🔗 参考:

44. CVE-2026-54754 `CVSS 9.6`

🎯 受影响:Klever-Go

📋 简介:Klever-Go is the Go implementation of the Klever blockchain protocol.

🔗 参考:

45. CVE-2026-54755 `CVSS 9.6`

🎯 受影响:Klever-Go

📋 简介:Klever-Go is the Go implementation of the Klever blockchain protocol.

🔗 参考:

46. CVE-2026-82078 `CVSS 9.4`

🎯 受影响:An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCu

📋 简介:An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG.

🔗 参考:

47. CVE-2026-55220 `CVSS 9.3`

🎯 受影响:Pimcore

📋 简介:Pimcore is an Open Source Data & Experience Management Platform.

🔗 参考:

48. CVE-2026-78174 `CVSS 9.3`

🎯 受影响:WatchGuard Dimension records unredacted session identifiers for logged-in users in its web UI diagno

📋 简介:WatchGuard Dimension records unredacted session identifiers for logged-in users in its web UI diagnostic log.

🔗 参考:

49. CVE-2026-82090 `CVSS 9.2`

🎯 受影响:Pocket through 8.33.0.0

📋 简介:Pocket through 8.33.0.0 allows XSS because "Save to Pocket" injects external HTML into the DOM.

🔗 参考:

50. CVE-2026-18918 `CVSS 9.1`

🎯 受影响:In Eclipse Lyo

📋 简介:In Eclipse Lyo versions 2.0.0 to 7.0.0, OAuth server authorization checks can be bypassed when the 2-legged auth is supported by the server.

🔗 参考:

51. CVE-2026-42007 `CVSS 9.1`

🎯 受影响:An attacker that has valid credentials can use a Sieve script with the editheader extension to trigg

📋 简介:An attacker that has valid credentials can use a Sieve script with the editheader extension to trigger a use-after-free in the mail editing code, and to write memory contents beyond the intended buffer into the delivered mail.

🔗 参考:

52. CVE-2026-50152 `CVSS 9.1`

🎯 受影响:Ceph

📋 简介:Ceph is an open-source distributed storage platform providing object, block, and file storage.

🔗 参考:

53. CVE-2026-55247 `CVSS 9.1`

🎯 受影响:plone.app.event provides the event content type for Plone. Prior to

📋 简介:plone.app.event provides the event content type for Plone.

🔗 参考:

54. CVE-2026-55248 `CVSS 9.1`

🎯 受影响:plone.app.portlets provides portlets and a Plone-specific user interface for plone.portlets. Prior t

📋 简介:plone.app.portlets provides portlets and a Plone-specific user interface for plone.portlets.

🔗 参考:

55. CVE-2026-55511 `CVSS 9.1`

🎯 受影响:Yamcs

📋 简介:Yamcs is a mission control framework.

🔗 参考:

56. CVE-2026-82281 `CVSS 9.1`

🎯 受影响:Kotaemon through 0.12.0 fails to properly validate conversation ownership in select_conv, delete_con

📋 简介:Kotaemon through 0.12.0 fails to properly validate conversation ownership in select_conv, delete_conv, rename_conv, and on_set_public_conversation functions in control.py.

🔗 参考:

57. CVE-2026-40541 `CVSS 9`

🎯 受影响:An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerabilit

📋 简介:An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain in Synology Chat Server before 2.4.5-22148 allows remote authenticated users, via a UI interaction, to read or write arbitrary files and conduct denial-of-se...

🔗 参考:

58. CVE-2026-82021 `CVSS 9`

🎯 受影响:Hermes Agent 0.18.2

📋 简介:Hermes Agent 0.18.2 prior to 0.19.0 contains a supply chain vulnerability in its bundled MCP catalog that allows a remote attacker to execute arbitrary code by compromising a third-party upstream repository referenced via a mutable branch rather than a pinned commit SHA.

🔗 参考:

🟠 HIGH · 10 条

1. CVE-2025-30156 `CVSS 8.9`

🎯 受影响:Ceph

📋 简介:Ceph is an open-source distributed storage platform providing object, block, and file storage.

🔗 参考:

2. CVE-2026-39944 `CVSS 8.8`

🎯 受影响:Ceph

📋 简介:Ceph is an open-source distributed storage platform providing object, block, and file storage.

🔗 参考:

3. CVE-2026-82282 `CVSS 8.8`

🎯 受影响:Atlantis through 0.47.1 fails to authenticate the /github-app/setup endpoint, allowing unauthenticat

📋 简介:Atlantis through 0.47.1 fails to authenticate the /github-app/setup endpoint, allowing unauthenticated attackers to access GitHub App credentials.

🔗 参考:

4. CVE-2026-81517 `CVSS 8.7`

🎯 受影响:An unauthenticated party able to reach the port of a MongoDB Connector for BI (mongosqld) instance m

📋 简介:An unauthenticated party able to reach the port of a MongoDB Connector for BI (mongosqld) instance may generate enough routine connection log activity to exhaust the storage backing the configured log path.

🔗 参考:

5. CVE-2026-54085 `CVSS 7.1`

🎯 受影响:Wazuh

📋 简介:Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads.

🔗 参考:

6. CVE-2026-55066 `CVSS 7.1`

🎯 受影响:Vikunja

📋 简介:Vikunja is an open-source self-hosted task management platform.

🔗 参考:

7. CVE-2026-55848 `CVSS 8.6`

🎯 受影响:mapfish-print

📋 简介:mapfish-print is a component of MapFish for printing templated cartographic maps.

🔗 参考:

8. CVE-2026-82271 `CVSS 7.1`

🎯 受影响:R2R through 3.6.5 fails to properly validate user ownership in conversation update and message handl

📋 简介:R2R through 3.6.5 fails to properly validate user ownership in conversation update and message handlers, allowing authenticated users to modify other users' conversations.

🔗 参考:

9. CVE-2026-82280 `CVSS 7.1`

🎯 受影响:Quivr through 0.0.322 fails to validate ownership in prompt endpoints, allowing authenticated users

📋 简介:Quivr through 0.0.322 fails to validate ownership in prompt endpoints, allowing authenticated users to modify any prompt by identifier.

🔗 参考:

10. CVE-2026-61783 `CVSS 7`

🎯 受影响:Wazuh

📋 简介:Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads.

🔗 参考:

---

新发现 282 条 · 热度升级 0 条 · 🔥=高热度/有 PoC · 🆙=昨日已推、今日热度升级

📊 GitHub 热榜

📊 GitHub 日榜 · 2026-08-29

1. tt-a1i/archify

📋 Agent skill for beautiful, verifiable architecture, workflow, sequence, data-flow, and lifecycle diagrams—self-contained HTML with motion and crisp export.

2. K-Dense-AI/scientific-agent-skills

📋 Turn any AI agent into an AI Scientist. The #1 Agent Skills library for science, used by 175,000+ scientists worldwide. 163 ready-to-use validated skills plus 100+ scientific databases covering biology, chemistry, medicine, and drug discovery. Compatible with Cursor, Claude Code, Codex, Pi, Antigravity, and the open Agent Skills standard.

3. anthropics/claude-plugins-official

📋 Official, Anthropic-managed directory of high quality Claude Code Plugins.

4. bilawalsidhu/gods-eye-view

📋 A spy satellite simulator in your browser, except the data is real. Live open source spatial intelligence on a photorealistic 3D globe.

5. abhigyanpatwari/GitNexus

📋 GitNexus: The Zero-Server Code Intelligence Engine - GitNexus is a client-side knowledge graph creator that runs entirely in your browser. Drop in a git repository (Github, Gitlab, Azure, Local) or ZIP file, and get an interactive knowledge graph with a built in Graph RAG Agent. Perfect for code exploration

6. JetBrains/go-modern-guidelines

📋 Help AI coding agents write modern Go

7. calesthio/OpenMontage

📋 World's first open-source, agentic video production system. 12 production pipelines, 100+ tools, 700+ agent skill and production-knowledge files. Turn your AI coding assistant into a full video production studio.

8. abi/screenshot-to-code

📋 Drop in a screenshot and convert it to clean code (HTML/Tailwind/React/Vue)

9. cursor/plugins

📋 Cursor plugin specification and official plugins

10. freestylefly/awesome-gpt-image-2

📋 Prompt as Code | GPT-Image2 工业级提示词引擎与模板库,530+ 个案例逆向工程,20+ 套工业级模板,并提炼出Skills,持续更新中

🤖 AI 总结分析

今日整体形势呈现“高危漏洞集中爆发、AI 应用与数据基础设施成重点靶标”的特征。高危漏洞预警显示 58 条 CRITICAL 级条目,数量级偏高,且多个漏洞涉及默认配置缺陷、认证绕过与未授权远程代码执行,攻击者利用门槛低、影响面大。安全热点明显向 AI/LLM 开源平台流数据处理组件倾斜,技术趋势是围绕自动化接口和默认信任边界实施链式利用。

每日高危漏洞预警中,最值得关注的是 CVE-2026-9198:Langflow 1.0.0 至 1.10.0 版本可被未认证攻击者通过 `/api/v1/auto_login` 铸造 SUPERUSER 令牌,再调用 `/api/v1/validate/code` 执行 `exec()`,形成完整 RCE 链,且参考链接显示已进入 CISA KEV 并存在公开 PoC,现实危害迫在眉睫。另一项 CVE-2026-82266 同样危险:Redpanda 26.2.2 及之前版本将 Admin API 绑定在 `0.0.0.0:9644` 且默认不要求认证,未认证请求被直接视为超级用户,意味着暴露在公网的 Redpanda 实例可被瞬间接管。

每日安全情报今日暂无新增条目,可能与数据源更新节奏或当日事件沉淀不足有关,但这并不代表威胁水平下降,尤其是上述漏洞已存在公开利用迹象,仍需以漏洞预警为行动依据。

GitHub 热榜虽无直接安全工具上榜,但 anthropics/claude-plugins-officialK-Dense-AI/scientific-agent-skills 等项目反映出 AI 编码代理的插件与技能库生态正在快速扩张;这些被开发者直接引入本地环境的组件一旦被投毒或引入恶意依赖,将成为新的供应链攻击入口,与今日 AI 平台漏洞风险形成上下游共振。

基于以上分析,今天应优先排查并修复所有暴露在公网的 Langflow 实例,确认版本是否落在 1.0.0 至 1.10.0 区间,并立即升级到 1.8.2 以上版本;若无法即时升级,应先行限制网络访问或关闭相关接口。